Home Rogue Websites Cleanerpcsolution.com

Cleanerpcsolution.com

Posted: April 7, 2009

Cleanerpcsolution.com specializes in hijacking the web browsers on computers infected with Trojans that are related to the rogue anti-spyware application called Cleaner2009. The aforementioned Trojans are dropped undetected onto the target PC, where they modify web browser settings on the compromised machine.

During web-surfing activities, you will be automatically diverted to the Cleanerpcsolution.com web page without consent, where annoying pop-ups and alert messages will inform you that your system contains strictly private information that should not fall into the hands of cyber-thieves. Cleaner2009 is suggested as a means to keep this information safe from any future attacks, however, Cleaner2009 is worthless malware that can neither detect nor remove any computer infections.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CurrentFolder%\log
    2 %Documents and Settings%\All Users\Start Menu\Programs\Cleaner 2009\Register Cleaner 2009.lnk
    3 %Documents and Settings%\All Users\Start Menu\Programs\Cleaner 2009\Start Cleaner 2009.lnk
    4 %Documents and Settings%\All Users\Start Menu\Programs\Cleaner 2009\Uninstall Cleaner 2009.lnk
    5 %ProgramFiles%\Cleaner 2009\Cleaner 2009.db
    6 %ProgramFiles%\Cleaner 2009\Cleaner 2009.exe
    7 %ProgramFiles%\Cleaner 2009\Cleaner2009.pkg
    8 %ProgramFiles%\Cleaner 2009\com\pcsd.dll
    9 %ProgramFiles%\Cleaner 2009\program.info
    10 %ProgramFiles%\Cleaner 2009\Uninstall.exe
    11 %UserProfile%\Application Data\Cleaner 2009\log.dat
    12 %UserProfile%\Application Data\Cleaner 2009\settings.dat
    13 %UserProfile%\Desktop\Cleaner 2009.lnk
    14 %UserProfile%\Local Settings\Temp\[RANDOM FILE NAME].tmp
    15 Cleaner2009.exe
    16 Cleaner2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USERS\Software\Cleaner 2009HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{82297D11-31C1-40B1-960A-BDF40B3B365F}HKEY_LOCAL_MACHINE\SOFTWARE\Cleaner 2009HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\pcsdHKEY_CLASSES_ROOT\CLSID\{82297D11-31C1-40B1-960A-BDF40B3B365F}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Cleaner 2009
Loading...